Skip to main content
GET
Get a single audit log entry by ID

Authorizations

Authorization
string
header
required

API key issued per entity via Settings > Developers > API Keys. Each key carries scopes (e.g. orders:read, products:write). Bearer token format: Authorization: Bearer ark_live_ent_ Test keys use ark_test_ent_. Both are issued per entity via Settings > Developers > API Keys.

Path Parameters

id
string<uuid>
required

Query Parameters

expand
enum<string>[]

actor: resolve actor name/email from users table. resource: join full resource row (product, order, account, etc.). diff: include before_state, after_state, diff JSONB. chain: include prev_hash, entry_hash, archived_at.

Available options:
actor,
resource,
diff,
chain

Response

Single audit log entry

A single audit log entry from activity_log. Audit log entries are created automatically by canonical handlers via logActivity() and are immutable. The public API exposes read-only access only (Rule 20, append-only design). Chain integrity fields (prev_hash, entry_hash) are included when expand[]=chain is requested.

id
string<uuid>
object
enum<string>
Available options:
audit_log_entry
entity_id
string<uuid>
actor
object

Actor who performed the action. Resolved from metadata.actor JSONB.

action
string

Dot-namespaced action slug, e.g. order.created.

resource
object
description
string | null
metadata
object | null

Arbitrary JSONB payload. Internal keys (_actor, _api_key_id, etc.) prefixed with underscore.

ip_address
string | null
user_agent
string | null
session_id
string | null
request_id
string | null
severity
enum<string> | null
Available options:
info,
warning,
critical,
security
outcome
enum<string> | null
Available options:
success,
failure
error_code
string | null
before_state
any | null

State before the action. Present when expand[]=diff.

after_state
any | null

State after the action. Present when expand[]=diff.

diff
any | null

Computed diff of before/after state. Present when expand[]=diff.

_chain
object | null

Cryptographic chain fields. Present when expand[]=chain.

created_at
string<date-time>